Management device, control method for management device, and program

By generating and saving electronic certificates, the problem of difficulty in confirming the intention of the signer in existing technologies is solved, and the transparency and traceability of electronic signatures are achieved.

CN120660105APending Publication Date: 2025-09-16LE TECHS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202480011622.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-19
Filing Date
2024-03-01
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In existing electronic signature management systems, it is difficult to confirm the signatory's intention to sign electronically.

Method used

The electronic certificate is generated and stored by the management device, including signature content information, for confirming the intention of the signer.

Benefits of technology

It realizes the confirmation of the signatory's intention and ensures the transparency and traceability of the electronic signature.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120660105A_ABST
    Figure CN120660105A_ABST
Patent Text Reader

Abstract

A management device according to an embodiment of the present invention is a management device for managing an electronic signature for electronic content, and is provided with: an instruction acquisition unit for acquiring an instruction to be signed for electronic content and signature content information that is information indicating the signed content; a signature generation unit that generates an electronic signature in response to the instruction; an assigning unit that assigns the generated electronic signature to the electronic content; an electronic certificate generation unit that generates an electronic certificate related to the electronic signature and including signature content information; and a storage unit that stores the electronic certificate in a predetermined storage unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a management device, a control method for the management device, and a program. Background Art

[0002] It is known to apply electronic signatures to electronic contents such as electronic documents for the purpose of proving that they have not been altered, etc. For example, an electronic signature management system has been proposed that applies electronic signatures to signature target data (see, for example, Patent Document 1).

[0003] Prior art literature

[0004] Patent Literature

[0005] Patent Document 1: Japanese Patent Application Publication No. 2018-067807 Summary of the Invention

[0006] However, the signature value generated in the electronic signature management system of Patent Document 1 cannot include, for example, items arbitrarily input by the signatory. Therefore, it is difficult to understand the intention of the party who electronically signed the electronic content.

[0007] Therefore, the present invention has been made in view of the above-mentioned conventional actual situation, and an object of the present invention is to provide a management device, a control method for the management device, and a program that can confirm the intention of the signer to electronically sign.

[0008] A management device according to an embodiment of the present invention is a management device for managing electronic signatures for electronic content, and comprises: an instruction acquisition unit for acquiring an instruction for signing electronic content and signature content information representing the content of the signature; a signature generation unit for generating an electronic signature in response to the instruction; an assignment unit for assigning the generated electronic signature to the electronic content; an electronic certificate generation unit for generating an electronic certificate, the electronic certificate being associated with the electronic signature and including the signature content information; and a storage unit for storing the electronic certificate in a predetermined storage unit.

[0009] Thus, when an electronic signature is applied to electronic content in response to a signature instruction, an electronic certificate containing signature content information indicating the content of the signature applied to the electronic content is stored in a predetermined storage unit. Thus, since the signature content information is recorded in the electronic certificate, the signatory's intention to apply the electronic signature can be confirmed by checking the electronic certificate.

[0010] Effects of the Invention

[0011] According to the present invention, it is possible to confirm the signatory's intention to electronically sign. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1This is a schematic diagram showing the outline of an electronic signature management system 100 using the management device 1 according to the embodiment.

[0013] Figure 2 1 is a schematic diagram showing an electronic document D to which an electronic signature S generated by the management device 1 according to the embodiment is attached.

[0014] Figure 3 It is a block diagram showing the configuration of the management device 1 according to the embodiment.

[0015] Figure 4 This is a schematic diagram showing an example of the data structure of an electronic certificate according to the embodiment.

[0016] Figure 5 It is a block diagram showing the configuration of the user terminal 4 according to the embodiment.

[0017] Figure 6A This is a sequence diagram showing an example of the operation process executed by the electronic signature management system 100 according to the embodiment.

[0018] Figure 6B This is a sequence diagram showing another example of the operation process executed by the electronic signature management system 100 according to the embodiment.

[0019] Figure 6C This is a sequence diagram showing another example of the operation process executed by the electronic signature management system 100 according to the embodiment.

[0020] Description of Reference Numerals

[0021] 1…management device, 2…electronic content database, 3…electronic certificate database, 4, 4A, 4B, 4C, 4D…user terminal, 11…document management unit, 12…instruction acquisition unit, 13…user information acquisition unit, 14…signature generation unit, 15…assignment unit, 16…electronic certificate generation unit, 17…electronic certificate storage unit, 18…transmitter / receiver unit, 41…camera unit, 42…identifier acquisition unit, 43…saved information acquisition unit, 44…hash value calculation unit, 45…consistency confirmation unit, 46…output unit, 47…operation acceptance unit, 48…transmitter / receiver unit, N…communication network, S…electronic signature, D…electronic content, D0, D1, D2, D3, D4, D5…electronic document. DETAILED DESCRIPTION

[0022] Preferred embodiments of the present invention will be described with reference to the accompanying drawings. (In each drawing, parts denoted by the same reference numerals have the same or similar configurations.)

[0023] (1) Summary

[0024] Figure 1 This is a schematic diagram showing the outline of an electronic signature management system 100 using the management device 1 according to the embodiment.

[0025] like Figure 1 As shown, the electronic signature management system 100 includes, for example, a management device 1, an electronic content database 2, an electronic certificate database 3, and a plurality of user terminals 4. The management device 1 is connected to the electronic content database 2 and the electronic certificate database 3 so that it can manage (save, delete, modify, etc.) the information stored in these databases. Furthermore, the management device 1 is connected to the plurality of user terminals via a communication network N such as the Internet so that they can exchange information.

[0026] In this embodiment, for example, users include an order-taking company that accepts orders for goods / services, an ordering company that orders goods / services from the order-taking company, a factoring company that factors the claims related to the orders and orders between the order-taking company and the ordering company, and a collection company that collects the transfer fee in the factoring. Furthermore, for example, multiple user terminals 4 include a user terminal 4A used by the order-taking company, a user terminal 4B used by the ordering company, a user terminal 4C used by the factoring company, and a user terminal 4D used by the person in charge of the collection company.

[0027] The management device 1 is, for example, a computer (information processing device) such as a server, and includes a processing unit such as a CPU and a storage unit such as a memory. The management device 1 generates an electronic signature S for electronic content D, such as a user's contract. The electronic content D is stored, for example, in an electronic content database 2. Specifically, the management device 1 has the function of generating an electronic signature S for the user's electronic content D. By assigning the electronic signature S to the electronic content D in a visually recognizable manner, the management device 1 can generate electronic content D that expresses, for example, consent to the electronic content D.

[0028] Furthermore, in the following embodiments, "electronic content" may include "electronic documents" or "electronic images". "Electronic content" may refer to any document such as a contract, quotation, application, order list, delivery note, payment request, receipt, invoice, meeting minutes, payment request, application form, signature book, etc., and may also include documents generated electronically. Furthermore, an "electronic image" may be a still image or an animation (image) consisting of a plurality of still images that are continuous in time sequence. The animation may be combined with sound. Furthermore, "electronic signature" may include the process of electronically stamping electronic content D on a paper contract, etc. Furthermore, an "electronic certificate" may be a certificate used to certify matters related to electronic signatures, and may, for example, include an electromagnetic record produced to prove that a matter used to confirm that a user has signed an electronic signature is related to the user.

[0029] Management device 1 Figure 1 As shown, it is connected to the electronic certificate database 3. The management device 1 generates an electronic certificate for electronic content D with an electronic signature S. The management device 1 stores the generated electronic certificate for electronic content D in the electronic certificate database 3. The electronic certificate database 3 may also be composed of, for example, multiple node computers storing a blockchain. The form of the blockchain is not particularly limited and may, for example, be a consortium-type private blockchain. The management device 1 stores the electronic certificate in the electronic certificate database 3, which is composed of, for example, such a blockchain.

[0030] Figure 2 1 is a schematic diagram showing an electronic document D to which an electronic signature S is attached, generated by the management apparatus 1 according to the embodiment. Figure 2 As shown, a visually recognizable electronic signature S can be assigned to the electronic document D. For example, the management device 1 assigns the electronic signature S corresponding to each user in a visually recognizable manner. For example, the management device 1 can assign the electronic signature S displayed as a QR code (registered trademark) to the electronic content D. Furthermore, when assigning the electronic signature S to an electronic image serving as electronic content, the management device 1 can superimpose the electronic signature S on a portion of at least one still image included in the electronic image, or can assign the electronic signature S to metadata contained in the electronic image.

[0031] like Figure 1 As shown, the user terminal 4 is configured as a separate device from the management device 1. The user terminal 4 is, for example, a computer (information processing device) such as a smartphone, tablet computer, or personal computer with a camera function, and includes a processing unit such as a CPU and a storage unit such as a memory. Based on the electronic signature S generated by the management device 1, the user terminal 4 retrieves information contained in the electronic certificate stored in the electronic certificate database 3 and, based on this information, performs processing to verify the authenticity of the electronic content D. Furthermore, the user terminal 4 performs various information display processing based on the information contained in the retrieved electronic certificate. In particular, the user terminal 4 displays a URL identifying the storage area in the electronic content database 2 where the electronic content D is stored. When the user selects this URL, the user terminal 4 retrieves the electronic content D from the electronic content database 2 and displays it. This allows the content of the electronic content D to be verified in an environment where the authenticity of the electronic content D is guaranteed. Furthermore, since the content of the electronic content D can be verified based on the electronic signature S, the user can also maintain the weight of evidence (based on the information in the electronic certificate) by storing, for example, printed paper of the electronic content D, rather than a physical document of the electronic content D.

[0032] (2) Composition

[0033] (2-1) Management device 1

[0034] Figure 3 This is a block diagram showing the configuration of a management device 1 according to an embodiment. The management device 1 includes a document management unit 11, an instruction acquisition unit 12, a user information acquisition unit 13, a signature generation unit 14, an assignment unit 15, an electronic certificate generation unit 16, an electronic certificate storage unit 17, and a transceiver unit 18. These various functional units are implemented by the operation of a processing unit such as a CPU included in the management device 1.

[0035] The document management unit 11 is implemented, for example, by the operation of a CPU. The document management unit 11 performs operations such as generating, acquiring, modifying, and storing electronic content subject to electronic signatures in a storage unit. For example, the document management unit 11 acquires electronic content D from the electronic content database 2 or the user terminal 4. The electronic content D may be electronic data generated by document generation software or image generation software, or data obtained by scanning printed materials such as paper. Furthermore, the document management unit 11 may generate and modify electronic content based on instructions received from the user terminal 4. Furthermore, the document management unit 11 may store electronic content in the electronic content database 2.

[0036] The instruction acquisition unit 12 acquires an instruction (signature instruction) to sign the acquired electronic content D that is a signature target. The instruction acquisition unit 12 acquires the signature instruction from the user terminal 4 , for example.

[0037] The user information acquisition unit 13 acquires user information as user information. Furthermore, in this embodiment, the user information acquisition unit 13 acquires the user's pre-issued user ID and user name. Here, the user information acquisition unit 13 acquires the user IDs and user names of each contractor (user) as user information. Furthermore, in this embodiment, the user information acquisition unit 13 acquires user information when generating electronic signatures S from users of two legal entities. User information may also include arbitrary information specific to the user managed by the user.

[0038] The signature generation unit 14 generates an electronic signature S that encodes the electronic certificate identifier, which serves as the identifier of the electronic certificate. Alternatively, the signature generation unit 14 may include a unique string in the electronic certificate identifier. This string may be unique for each electronic signature S, for example. The electronic certificate identifier is generated (numbered), for example, by assigning the electronic signature S to electronic content D.

[0039] The assigning unit 15 assigns the generated electronic signature S to the electronic content D. The assigning unit 15 may assign the electronic signature S to the electronic content D so that the electronic signature S can be visually recognized. In this way, it is easy to recognize that the electronic signature S has been assigned to the electronic content D. Figure 2As shown in FIG. 1 , the assigning unit 15 can assign the electronic signature S generated in the position displayed in parallel to the legal person name and the name of the representative of the user information recorded in the electronic content D. The assigning unit 15 can assign the electronic signature S to the position of the electronic signature S corresponding to the user information recorded in the electronic content D. In this embodiment, the assigning unit 15 can also write the user's name included in the acquired user information into the electronic signature S. Figure 2 As shown, the assigning unit 15 writes the user name along with the corresponding user's electronic signature S (QR code) at the bottom of the display surface of the electronic content D (electronic document). This makes it clear which user's electronic signature S is. Furthermore, by writing the encoded electronic signature S together, the code can be treated like a print, creating a visual effect similar to a stamp on paper.

[0040] The electronic certificate generating unit 16 generates various electronic certificates related to the electronic signature S. The electronic certificates are stored in the electronic certificate database 3, for example.

[0041] The electronic certificate storage unit 17 stores the generated electronic certificate in the electronic certificate database 3 .

[0042] Figure 4 : is a schematic diagram showing an example of the data structure of the electronic certificate stored in the electronic certificate database 3. Figure 4 Each row shown corresponds to one electronic certificate. For example, each electronic certificate is added to the electronic certificate database 3 each time an electronic signature is given to electronic content.

[0043] The electronic certificate includes, for example, the issuer name, issue number, issue date and time, expiration date of validity period, series ID, sub-number, user ID, user organization, user position, user name, signature content, original text hash value, hash value before signature, hash value after signature, URL for publicizing electronic content, and password.

[0044] The issuer name is the name of the issuer of the electronic certificate, and may also be, for example, the name of the administrator of the management device 1. The issue number is the identifier of the electronic certificate issued by the management device 1 (an identifier used to identify the electronic certificate). The issue date and time is the date and time the electronic certificate was issued, and may also be information about the moment the signature was signed. The issue date and time is an example of ranking information indicating the ranking of the electronic signature (information indicating that each time an electronic signature is assigned, the electronic signature ranks among a series of electronic signatures). The validity period expiration date is the date when the validity period of the electronic certificate expires.

[0045] The series ID is an example of system identification information that is identification information of the system for identifying electronic content D. The series ID does not change even if one or more electronic signatures S are assigned to the electronic content D, and can be identification information inherent to (the system of) the electronic content D. In other words, the series ID is identification information assigned relative to the content represented by the electronic content D (which may also include modified content). Therefore, when electronic signatures S are continuously assigned to the electronic content D, the electronic content D or a series of electronic signatures S can be managed as a series, and it can be confirmed whether a certain electronic signature S in the series of electronic signatures S is the latest, whether the electronic signature marked in the held electronic content D is the latest, etc.

[0046] The fractional number is an example of ranking information indicating the ranking of the electronic signature S (information indicating that each time an electronic signature S is given, the electronic signature S is ranked among a series of electronic signatures S). Figure 4 In the example shown, natural numbers such as 1, 2, and 3 are used as the score numbers, but the score numbers (ranking information) can be arbitrarily composed of symbols or signs as long as the ranking can be displayed.

[0047] The user ID is the user's identification information. The user's organization is information indicating the organization to which the user belongs. The user's position is information indicating the user's position in the organization. The user name is the user's name (the name of the person in charge of each company).

[0048] The signature content is information attached to the electronic signature S, and can also be text data arbitrarily entered by the user. For example, the signature content can indicate the user's intention attached to the electronic signature. In the case of modifications to the electronic content being signed, it can also indicate the existence of modifications or the content of the modifications. Thus, by verifying the electronic certificate, it is possible to confirm the existence of the user's intention regarding the electronic signature, the existence of modifications to the electronic content, and the content of the modifications.

[0049] The original hash value, the pre-signed hash value, and the post-signed hash value are used, for example, in consistency verification processing related to electronic content D. The consistency verification process will be described later. The original hash value is the hash value of electronic content D (original text) that does not contain any electronic signatures. The pre-signed hash value is the hash value of electronic content D (electronic content D containing an electronic signature S that ranks higher than the electronic signature S) immediately before the latest electronic signature S is assigned. The post-signed hash value is the hash value of electronic content D after the latest electronic signature S is assigned.

[0050] The electronic content public URL may be a URL for identifying a storage area storing electronic content D (e.g., a URL for electronic content D in the electronic content database 2). An expiration date may also be set for the electronic content public URL. The password may be a password required to access the electronic content public URL and browse the electronic content D, or may be assigned arbitrarily or by the system.

[0051] The above-mentioned electronic certificates are merely examples, and the electronic certificate in this embodiment may not include any of the above-mentioned items, or may include items other than the above-mentioned items.

[0052] The transceiver 18 transmits and receives various information to and from the user terminal 4. For example, the transceiver 18 receives a signature instruction for the electronic content D from the user terminal 4. Furthermore, the transceiver 18 transmits the electronic content D (including the electronic signature S) to the user terminal 4, for example.

[0053] Each component included in the management device 1 can be implemented by hardware, software or a combination thereof. Here, implementation by software means implementation by reading a program into a computer and executing it. The program is stored using various types of non-transitory computer readable media (non-transitory computer readable medium) and can be supplied to a computer. Non-transitory computer readable media include various types of tangible storage media (tangible storage medium). Examples of non-transitory computer readable media include magnetic storage media (e.g., floppy disks, magnetic tapes, hard disk drives), optical magnetic storage media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, semiconductor memories (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, RAMs (Random access memory)). In addition, the display program can also be supplied to a computer via various types of transitory computer readable media (transitory computer readable medium). Examples of transitory computer readable media include electrical signals, optical signals, and electromagnetic waves. Transitory computer-readable media can supply the program to a computer via a wired communication line such as electric wires and optical fibers, or a wireless communication line.

[0054] (2-2) User Terminal 4

[0055] Figure 5This is a block diagram showing the configuration of a user terminal 4 according to an embodiment. The user terminal 4 includes an imaging unit 41, an identifier acquisition unit 42, a stored information acquisition unit 43, a hash value calculation unit 44, a consistency check unit 45, an output unit 46, and an operation reception unit 47. These various functional units are implemented by the operation of a processing unit such as a CPU included in the user terminal 4.

[0056] The imaging unit 41 is a so-called imaging mechanism including a camera. The imaging unit 41 captures, for example, an arbitrary electronic signature S attached to electronic content D. The imaging unit 41 captures, for example, an arbitrary electronic signature S included in electronic content D displayed on a display unit (not shown) of another terminal.

[0057] The identifier acquisition unit 42 captures an image of the electronic signature S (QR code) to acquire an electronic certificate identifier including at least the captured electronic signature S.

[0058] The hash value calculation unit 44 calculates various hash values ​​based on the electronic content D. For example, the hash value calculation unit 44 may calculate a hash value for the electronic content D that includes the latest electronic signature S (post-signature hash value). Alternatively, the hash value calculation unit 44 may calculate a hash value for the electronic content D that does not include the latest electronic signature S (pre-signature hash value). Alternatively, the hash value calculation unit 44 may calculate a hash value for the original electronic content D that does not include any electronic signature S (original text hash value).

[0059] The consistency confirmation unit 45 performs a consistency confirmation process of the electronic content D related to the electronic content D based on the electronic certificate stored in the management device 1. Through the consistency confirmation process of the electronic content D, it is possible to determine whether the electronic content D is authentic. For example, the consistency confirmation unit 45 confirms the consistency of the hash value (original hash value, hash value before signature and / or hash value after signature) contained in the electronic certificate obtained from the management device 1 and the hash value (original hash value, hash value before signature and / or hash value after signature) calculated from the electronic content D by the hash value calculation unit 44 based on the electronic certificate identifier obtained by taking a picture of an arbitrary electronic signature S contained in the electronic content D. For example, the consistency confirmation unit 45 can also determine whether the original electronic content D has not been changed by determining whether the original hash value obtained from the electronic content D as the object is consistent with the original hash value contained in the electronic certificate. Furthermore, for example, the consistency check unit 45 may determine whether the electronic content D has not been altered between the time the previous electronic signature S was applied and the time the latest electronic signature S was applied, by determining whether the pre-signature hash value (a hash value calculated based on the electronic content obtained excluding the latest electronic signature) obtained from the target electronic content D is consistent with the post-signature hash value included in the immediately preceding electronic certificate. A specific operation example is as follows. Specifically, a user may access the electronic content D (original) stored in the management device 1 (or in the electronic content database 2, etc.) by, for example, capturing an image of the electronic signature S of the electronic content D printed on paper (hand-delivered, etc.) using the user terminal 4, and causing the user terminal 4 to display the electronic content D. The management device 1 may also calculate a hash value for the accessed electronic content D and compare it with the hash values ​​(original hash value, pre-signature hash value, and post-signature hash value) stored in the electronic certificate database 3 to determine whether the electronic content D is authentic. Regarding the electronic content D that has been handed over, the user can verify the authenticity of the electronic content D by, for example, visually comparing the electronic content D that has been handed over with the electronic content D stored in the management device 1 displayed on the user terminal 4. Furthermore, for example, the authenticity of the electronic content D stored in the management device 1 can be determined by querying the electronic certificate database 3.

[0060] The output unit 46 outputs various information related to the electronic content D. For example, the output unit 46 outputs information of various electronic certificates acquired from the electronic certificate database 3. Furthermore, for example, the output unit 46 outputs a consistency check result by the consistency check unit 45.

[0061] The operation accepting unit 47 accepts various user operations. For example, the operation accepting unit 47 accepts selection of consistency check processing related to the electronic content D. The operation accepting unit 47 also accepts selection of transitions to various screens displaying information related to the electronic content D or links.

[0062] The transceiver 48 transmits and receives various information between the management device 1 and other user terminals 4. For example, the transceiver 48 transmits a signature instruction for electronic content to the management device 1. Furthermore, the transceiver 48 receives, for example, electronic content D (including an electronic signature S) or an electronic certificate from the management device 1.

[0063] (3) Work example

[0064] Figures 6A to 6C This is a sequence diagram showing an example of the work processing performed by the electronic signature management system 100 involved in the embodiment. In the following, there is an order for goods / services provided by the order-receiving enterprise from the ordering enterprise, so the person in charge of the order-receiving enterprise becomes in a state of generating an electronic document D0 as a payment request form for the ordering enterprise of the goods / services. In addition, the generation of the electronic document D0 can be generated by the user terminal 4A using the electronic document generation service provided by the management device 1, or it can be generated using general document generation software that does not use such a generation service. In addition, the generated electronic document D0 can be stored in the electronic document database 2 by the management device 1, or it can be stored by the user terminal 4A in a storage unit that can be accessed by the user terminal 4A. In addition, this sequence diagram takes the case where the electronic signature management system 100 in this embodiment processes an electronic document as electronic content as an example, but is not limited to electronic documents and can also be applied to other electronic content such as electronic images.

[0065] (3-1) Occurrence of Creditor's Rights

[0066] Figure 6A This is a sequence diagram related to the occurrence of a claim. When user terminal 4A, used by the person in charge of the order-receiving enterprise, receives an instruction from the person in charge of the order-receiving enterprise to sign electronic document D0, the instruction to sign electronic document D0 is transmitted to management device 1 (S101). Management device 1 receives the instruction to sign electronic document D0 from user terminal 4A (S102).

[0067] The signature instruction for the electronic document D0 may include, for example, the data of the electronic document D0 itself, or may include information (such as a serial ID) for identifying the electronic document D0 stored in the electronic document database 2 or a storage unit accessible to the user terminal 4A. In addition, the signature instruction may also include, for example, any item stored in the electronic certificate database 3 (such as an item related to the person in charge of the order-receiving enterprise). In addition, the signature instruction may also include, for example, the signature content entered by the person in charge of the order-receiving enterprise. Figure 4 In the example shown, the signature content of "request for payment" input by the person in charge of the order-receiving company is shown.

[0068] Based on the signature instruction, the management device 1 generates an electronic signature S1 based on the person in charge of the order-receiving enterprise, or generates an electronic certificate (S103). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D0 just before the electronic signature S1 is assigned, and includes it in the electronic certificate as a pre-signature hash value. In addition, the management device 1 generates a hash value of the electronic document D1 after the electronic signature S1 is assigned, and includes it in the electronic certificate as a post-signature hash value. In addition, the management device 1 generates a hash value of the electronic document D0 that does not contain any electronic signature S, and includes it in the electronic certificate as an original hash value. The management device 1 will generate the generated electronic certificate (for example, Figure 4 The electronic certificate of the first line shown in FIG. 1 is stored in the electronic certificate database 3 (S104).

[0069] The management device 1 generates an electronic document D1 by assigning the generated electronic signature S1 to the electronic document D0. The management device 1 then sends the generated electronic document D1 to the user terminal 4A (S105). The user terminal 4A may also store the received electronic document D1 in a storage unit accessible to the user terminal 4A.

[0070] Based on an operation by the person in charge of the order-receiving company, user terminal 4A transmits electronic document D1 to user terminal 4B used by the person in charge of the ordering company (S106). Alternatively, electronic document D1 may be transmitted to user terminal 4B via management device 1. User terminal 4B receives electronic document D1 (S107). User terminal 4B may also store the received electronic document D1 in a storage unit accessible to user terminal 4B.

[0071] After appropriately confirming the contents of the received electronic document D1 (the contents of the invoice), the person in charge of the ordering company performs an operation to instruct the person in charge of the ordering company to sign the electronic document D1. When the user terminal 4B accepts this operation, it transmits the signature instruction for the electronic document D1 to the management device 1 (S108). The management device 1 receives the signature instruction for the electronic document D1 from the user terminal 4B (S109).

[0072] The signature instruction for the electronic document D1 may include, for example, the data of the electronic document D1 itself, or may include information (such as a serial ID) for identifying the electronic document D1 stored in the electronic document database 2 or a storage unit accessible to the user terminal 4B. In addition, the signature instruction may include, for example, any item stored in the electronic certificate database 3 (such as an item related to the person in charge of the ordering company). In addition, the signature instruction may also include, for example, the signature content entered by the person in charge of the ordering company. Figure 4 In the example shown, the signature content "Pay by Bill" input by the person in charge of the ordering company is shown.

[0073] The management device 1 generates an electronic signature S2 based on the person in charge of the ordering enterprise based on the signature instruction, or generates an electronic certificate (S110). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D1 just before the electronic signature S2 is assigned, and includes it in the electronic certificate as a pre-signature hash value. In addition, the management device 1 generates a hash value of the electronic document D2 after the electronic signature S2 is assigned, and includes it in the electronic certificate as a post-signature hash value. In addition, the management device 1 generates a hash value of the electronic document D0 that does not contain any electronic signature S, and includes it in the electronic certificate as an original hash value. The management device 1 will generate the generated electronic certificate (for example, Figure 4 The electronic certificate on the second line shown in FIG. 1 is stored in the electronic certificate database 3 (S111).

[0074] The management device 1 can also determine whether the content of the electronic document D1 has been changed. That is, the management device 1 can also determine whether the content of the electronic document D1 to which the electronic signature S2 is assigned has not been changed from the content of the previous electronic document D1 immediately after the electronic signature S1 was assigned. For example, when the management device 1 determines whether the content of the electronic document D1 to which the electronic signature S2 is assigned has been changed, Figure 4 The post-signature hash value of the electronic certificate on the first line is compared with the pre-signature hash value of the electronic certificate on the second line. If the two match, it is determined that the electronic document D1 has not been altered. If they do not match, it is determined that the electronic document D1 has been altered. The management device 1 may also output the determination result to the user terminal 4B, etc. This allows the person in charge of the ordering company to confirm the continuity of the content of the electronic document D1 when performing the electronic signature S2.

[0075] The management device 1 generates an electronic document D2 by assigning the generated electronic signature S2 to the electronic document D1. The management device 1 then sends the generated electronic document D2 to the user terminal 4B (S112). The user terminal 4B may also store the received electronic document D2 in a storage unit accessible to the user terminal 4B.

[0076] In response to an operation by the person in charge of the ordering company, user terminal 4B transmits the electronic document D2 to user terminal 4A, used by the person in charge of the ordering company (S113). Alternatively, the electronic document D2 may be transmitted to user terminal 4A via management device 1. User terminal 4A receives the electronic document D2 (S114). Furthermore, a notification of payment commitment may be transmitted from user terminal 4B to user terminal 4A, either via or without management device 1. User terminal 4A may also store the received electronic document D2 in a storage unit accessible to user terminal 4A.

[0077] (3-2) Transfer of Creditor's Rights

[0078] Figure 6B This is a sequence diagram related to the transfer of claims. User terminal 4A, used by the person in charge of the order-receiving enterprise, receives input of transfer conditions related to the claim, as indicated in electronic document D2, from the person in charge of the order-receiving enterprise (S201). The content of the transfer conditions is not particularly limited and may include any items related to the claim (such as amount and date). The input transfer conditions are transmitted from user terminal 4A to management device 1, which stores them in an accessible electronic document database 2.

[0079] In response to an operation by the factoring company's principal, user terminal 4C, used by the principal, performs a claim search process (S202). For example, user terminal 4C transmits a search request containing transfer conditions, such as the amount entered by the principal, to management device 1. In response to the search request received from user terminal 4C, management device 1 searches for claims using the transfer conditions included in the search request as a key, and transmits the search results to user terminal 4C.

[0080] Here, as a result of the search, electronic document D2 is found, and information related to electronic document D2 is transmitted from management device 1 to user terminal 4C. After confirming the information related to electronic document D2, the person in charge of the factoring company decides to purchase the claim associated with electronic document D2. He or she then inputs a purchase application for the claim into user terminal 4C. User terminal 4C transmits the purchase application to user terminal 4A, used by the person in charge of the order-taking company, which is the original creditor (S203). This transmission process may also be performed via management device 1.

[0081] When the person in charge of the order-taking company, the original creditor, confirms the transfer of the claim based on the purchase application from the person in charge of the factoring company, he or she inputs a signature instruction for electronic document D2, confirming the transfer of the claim, to user terminal 4A. In response to this operation, user terminal 4A transmits the signature instruction for electronic document D2 to management device 1 (S204). Management device 1 receives the signature instruction for electronic document D2 from user terminal 4A (S205).

[0082] The signature instruction for the electronic document D2 may include, for example, the data of the electronic document D2 itself, or may include information (such as a serial ID) for identifying the electronic document D2 stored in the electronic document database 2 or a storage unit accessible to the user terminal 4A. In addition, the signature instruction may include, for example, any item stored in the electronic certificate database 3 (such as an item related to the person in charge of the order-receiving enterprise). In addition, the signature instruction may also include, for example, the signature content entered by the person in charge of the order-receiving enterprise. Figure 4 In the example shown, the signature content entered by the person in charge of the order-receiving company is shown as "transferring the payment rights described in this payment invoice."

[0083] Based on the signature instruction, the management device 1 generates an electronic signature S3 based on the person in charge of the order-receiving enterprise, and also generates an electronic certificate (S206). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D2 just before the electronic signature S3 is assigned, and includes it in the electronic certificate as a hash value before the signature. In addition, the management device 1 generates a hash value of the electronic document D3 after the electronic signature S3 is assigned, and includes it in the electronic certificate as a hash value after the signature. In addition, the management device 1 generates a hash value of the electronic document D0 that does not contain any electronic signature S, and includes it in the electronic certificate as an original hash value. The management device 1 will generate the electronic certificate (for example, Figure 4 The electronic certificate on the third line shown in FIG. 1 is stored in the electronic certificate database 3 (S207).

[0084] The management device 1 can also determine whether the content of the electronic document D2 has been changed. That is, the management device 1 can also determine whether the content of the electronic document D2 to which the electronic signature S3 is assigned has been changed from the content of the previous electronic document D2 immediately after the electronic signature S2 was assigned. For example, the management device 1 may determine whether the content of the electronic document D2 to which the electronic signature S3 is assigned has been changed. Figure 4 The post-signature hash value of the electronic certificate on the second line is compared with the pre-signature hash value of the electronic certificate on the third line. If the two match, it is determined that electronic document D2 has not been altered. If they do not match, it is determined that electronic document D2 has been altered. The management device 1 may also output the determination result to the user terminal 4A, etc. This allows the person in charge of the order-receiving enterprise to confirm the continuity of the content of the electronic document D2 when performing the electronic signature S3.

[0085] The management device 1 generates an electronic document D3 by assigning the generated electronic signature S3 to the electronic document D2. The management device 1 then sends the generated electronic document D3 to the user terminal 4C (S208). The user terminal 4C may also store the received electronic document D3 in a storage unit accessible to the user terminal 4C.

[0086] User terminal 4C displays electronic document D3, and the person in charge of the factoring company confirms the contents of electronic document D3 (S209). When the person in charge of the factoring company enters the transfer fee into the account, user terminal 4C accepts the operation and executes the transfer fee entry process (S210). This transfer fee entry process, for example, involves remittance of the transfer fee from the factoring company's account to the collecting company's account. In response to the person in charge of the collecting company's operation, user terminal 4D, used by the person in charge of the collecting company, executes the transfer fee entry confirmation process received from user terminal 4C (S211).

[0087] After confirming the payment and receipt of the transfer fee, the person in charge of the factoring company, acting as the new creditor, inputs a signature instruction for electronic document D3 to user terminal 4C, thereby registering the assignment of the debt. In response to this operation, user terminal 4C transmits the signature instruction for electronic document D3 to management device 1 (S212). Management device 1 receives the signature instruction for electronic document D3 from user terminal 4C (S213).

[0088] The signature instruction for the electronic document D3 may include, for example, the data of the electronic document D3 itself, or may include information (such as a serial ID) for identifying the electronic document D3 stored in the electronic document database 2. In addition, the signature instruction may also include, for example, any item stored in the electronic certificate database 3 (such as an item related to the person in charge of the order-taking enterprise). In addition, the signature instruction may also include, for example, the signature content entered by the person in charge of the factoring enterprise. Figure 4 In the example shown, the signature content is shown as "I have acquired the right to claim the payment stated in this payment request form."

[0089] The management device 1 generates an electronic signature S4 based on the person in charge of the order-receiving enterprise based on the signature instruction, or generates an electronic certificate (S214). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D3 just before the electronic signature S4 is assigned, and includes it in the electronic certificate as a hash value before the signature. In addition, the management device 1 generates a hash value of the electronic document D4 after the electronic signature S4 is assigned, and includes it in the electronic certificate as a hash value after the signature. In addition, the management device 1 generates a hash value of the electronic document D0 that does not contain any electronic signature S, and includes it in the electronic certificate as an original hash value. The management device 1 will generate the electronic certificate (for example, Figure 4 The electronic certificate on the fourth line shown in FIG. 1 is stored in the electronic certificate database 3 (S215).

[0090] The management device 1 can also determine whether the content of the electronic document D3 has been changed. That is, the management device 1 can also determine whether the content of the electronic document D3 to which the electronic signature S4 is assigned has been changed from the content of the previous electronic document D3 to which the electronic signature S3 has been assigned. For example, the management device 1 Figure 4 The post-signature hash value of the electronic certificate on the third line is compared with the pre-signature hash value of the electronic certificate on the fourth line. If the two match, it is determined that electronic document D3 has not been altered. If they do not match, it is determined that electronic document D3 has been altered. The management device 1 may also output the determination result to the user terminal 4C or the like. This allows the person in charge of the factoring company to confirm the continuity of the content of the electronic document D3 when performing the electronic signature S4.

[0091] The management apparatus 1 generates an electronic document D4 by adding the generated electronic signature S4 to the electronic document D3. The management apparatus 1 then transmits the generated electronic document D4 to the user terminal 4C (S216).

[0092] The user terminal 4C displays the electronic document D4, and the person in charge of the factoring company confirms the electronic document D4 (S217). When the person in charge of the factoring company performs a payment entrustment operation for the transfer money, the user terminal 4C accepts the operation and sends the payment entrustment of the transfer money to the user terminal 4D used by the person in charge of the collecting company (S218). When the user terminal 4D used by the person in charge of the collecting company receives the payment entrustment of the transfer money from the user terminal 4C, it responds to the operation of the person in charge of the collecting company and executes the payment processing of the transfer money (S219). Through the payment processing of the transfer money, for example, the transfer money is credited from the account of the collecting company to the account of the receiving company. The user terminal 4A used by the person in charge of the receiving company responds to the operation of the person in charge of the receiving company and executes the payment confirmation processing of the transfer money received from the user terminal 4D (S220).

[0093] (3-3) Extinction of Credit

[0094] Figure 6CThis is a sequence diagram related to the extinction of a debt. The user terminal 4B used by the person in charge of the ordering company executes payment processing of accounts payable related to the electronic document 4D in response to an operation by the person in charge of the ordering company (S301). Through the payment processing of accounts payable, for example, accounts payable are transferred from the account of the ordering company to the account of the collecting company. The user terminal 4D used by the person in charge of the collecting company executes confirmation processing of the entry of accounts payable received from the user terminal 4B in response to an operation by the person in charge of the collecting company (S302). The user terminal 4D used by the person in charge of the collecting company executes payment processing of accounts payable in response to an operation based on the person in charge of the collecting company (S303). Through the payment processing of accounts payable, for example, accounts payable are entered from the account of the collecting company to the account of the factoring company. The user terminal 4C used by the person in charge of the factoring company executes payment confirmation processing of accounts payable received from the user terminal 4D in response to an operation by the person in charge of the factoring company (S304).

[0095] After confirming payment of the accounts payable, the person in charge of the factoring company, acting as the new creditor, inputs a signature instruction for electronic document D4 to user terminal 4C, registering the extinction of the creditor's rights. In response to this operation, user terminal 4C transmits the signature instruction for electronic document D4 to management device 1 (S305). Management device 1 receives the signature instruction for electronic document D4 from user terminal 4C (S306).

[0096] The signature instruction for the electronic document D4 may include, for example, the data of the electronic document D4 itself, or may include information (such as a series ID) for identifying the electronic document D4 stored in the electronic document database 2. In addition, the signature instruction may also include, for example, any item stored in the electronic certificate database 3 (such as an item related to the person in charge of the factoring company). In addition, the signature instruction may also include, for example, the signature content entered by the person in charge of the factoring company. Figure 4 In the example shown, the signature content "Payment by Request" is shown.

[0097] Based on the signature instruction, the management device 1 generates an electronic signature S5 based on the person in charge of the factoring company, and also generates an electronic certificate (S307). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D4 just before the electronic signature S5 is assigned, and includes it in the electronic certificate as a hash value before the signature. In addition, the management device 1 generates a hash value of the electronic document D5 after the electronic signature S5 is assigned, and includes it in the electronic certificate as a hash value after the signature. In addition, the management device 1 generates a hash value of the electronic document D0 that does not contain any electronic signature S, and includes it in the electronic certificate as an original hash value. The management device 1 will generate the electronic certificate (for example, Figure 4The electronic certificate on the fifth line shown in FIG. 1 is stored in the electronic certificate database 3 (S308).

[0098] The management device 1 can also determine whether the content of the electronic document D4 has been changed. That is, the management device 1 can also determine whether the content of the electronic document D4 to which the electronic signature S5 is assigned has been changed from the content of the previous electronic document D4 immediately after the electronic signature S4 was assigned. For example, the management device 1 may determine whether the content of the electronic document D4 to which the electronic signature S5 is assigned has been changed. Figure 4 The post-signature hash value of the electronic certificate on the fourth line is compared with the pre-signature hash value of the electronic certificate on the fifth line. If the two match, it is determined that electronic document D4 has not been altered. If they do not match, it is determined that electronic document D4 has been altered. The management device 1 may also output the determination result to the user terminal 4C, etc. This allows the person in charge of the factoring company to confirm the continuity of the content of the electronic document D4 when performing the electronic signature S5.

[0099] The management device 1 adds the generated electronic signature S5 to the electronic document D4 to generate the electronic document D5. The management device 1 then sends the generated electronic document D5 to the user terminal 4C (S309). The user terminal 4C displays the electronic document D5, and the person in charge of the factoring company confirms the electronic document D5 (S310).

[0100] (4) Notes

[0101] In the above embodiment, the judgment process of whether the electronic content (electronic document) has been changed is performed at the time sequence of generating the electronic signature in response to the signature instruction (steps S110, S206, S214, S307). However, the judgment process of whether the change has occurred is not limited to these time sequences. For example, it can also be executed at a time sequence when the user requests the management device 1 to make a judgment via the user terminal 4 at an arbitrary time sequence. At this time, the user terminal 4 can also be, for example, the user receives information about the electronic signature specified as the object of the judgment process, and sends the information to the management device 1 including the judgment request. The management device 1 compares the pre-signature hash value of the specified electronic signature with the post-signature hash value of the previous electronic signature compared to the specified electronic signature. If the two are consistent, it is judged that the electronic document (electronic content) has not been changed when the specified electronic signature was used. If the two are inconsistent, it can also be judged that the electronic document (electronic content) has been changed when the specified electronic signature was used.

[0102] The electronic signature management system 100 described above can also be applied to situations where any user modifies the contents of a contract after the contract is signed. That is, first, for example, when a user needs to modify the contents of a signed contract (delivery date or amount, etc.), the user performs an operation on the user terminal 4 to obtain the electronic document that is the subject. Thus, the user terminal 4 obtains the electronic document that is the subject from the electronic document database 2 via the management device 1. Then, the user terminal 4 appropriately modifies the electronic document in response to the user's operation. Then, in response to the user's operation, the user terminal 4 sends a signature instruction for the modified electronic document (modified electronic document) to the management device 1. The management device 1 generates an electronic signature for the modified electronic document and assigns it to the modified electronic document.

[0103] The modified electronic document with an electronic signature can also be sent from the management device 1 to the user terminal 4 used by other users (the other party to the contract, etc.). Then, after confirming the content of the modified electronic document displayed on the user terminal 4, the other user performs the electronic signature operation on the modified electronic document relative to the user terminal 4. The user terminal 4 sends the signature instruction to the management device 1, and the management device 1 generates the electronic signature of the other user and further assigns it to the modified electronic document (the electronic document with the electronic signature of the above user). Thus, for example, the content of the contract can be modified on the file of the same electronic document without exchanging the modification memorandum. In previous electronic signatures, there are cases where the original electronic signature becomes improper by changing the content of the electronic document or the hash value based on it. On the other hand, in the electronic signature management system 100 involved in this embodiment, since even if the hash value of the electronic document changes due to the electronic signature, a series of electronic signatures associated with each other can be confirmed by the series ID (system identification information), it is also possible to simply manage the modification of the contract content.

[0104] Because the electronic signature management system 100 can identify a series of linked electronic signatures using a series ID (system identification information) even if the hash value of the electronic content changes due to the electronic signature, it is applicable not only to contracts but also to any electronic content, assuming that electronic signatures are continuously assigned. For example, the electronic signature management system 100 can also be used in situations such as signature campaigns in political events, where multiple signatories sequentially electronically sign electronic documents in a signature book.

Claims

1. A management device for managing electronic signatures for electronic content, comprising: an acquisition unit that acquires an instruction to sign the electronic content and signature content information that is information indicating the content of the signature; a signature generating unit, generating an electronic signature in response to the instruction; an assigning unit, which assigns the generated electronic signature to the electronic content; an electronic certificate generating unit, generating an electronic certificate, wherein the electronic certificate is associated with the electronic signature and includes signature content information; and The storage unit stores the electronic certificate in a predetermined storage unit.

2. The management device according to claim 1, wherein: The electronic signature includes an encoded identifier for identifying the electronic certificate.

3. The management device according to claim 1, wherein: The adding unit adds the electronic signature to the electronic content in a visually recognizable manner.

4. The management device according to claim 1, wherein: The electronic certificate generating unit further includes in the generated electronic certificate at least one of an original hash value which is a hash value of the electronic content not including any electronic signature, a pre-signature hash value which is a hash value of the electronic content before the electronic signature is assigned, and a post-signature hash value which is a hash value of the electronic content after the electronic signature is assigned.

5. The management device according to claim 4, wherein: The electronic certificate generating unit further includes ranking information indicating the ranking of the electronic signature in the generated electronic certificate. The management device further comprises: a comparing unit that compares the signed hash value included in one of the electronic certificates with the unsigned hash value included in the electronic certificate that includes the ranking information following the ranking information included in the one electronic certificate; and An output unit outputs a comparison result of the comparison unit. The management device according to claim 1 , wherein: The electronic content is an electronic document or an image.

7. A method for controlling a management device for managing electronic signatures for electronic content, comprising: a step of acquiring an instruction to sign the electronic content and signature content information representing the content of the signature; generating an electronic signature in response to the instruction; The step of assigning the generated electronic signature to the electronic content; The step of generating an electronic certificate related to the electronic signature and including the signature content information; and The step of storing the electronic certificate in a predetermined storage unit.

8. A program for causing an information processing device to function as a management device for managing electronic signatures for electronic content. The management device is made to function as the following components: an acquisition unit that acquires an instruction to sign the electronic content and signature content information that is information indicating the content of the signature; a signature generating unit, generating an electronic signature in response to the instruction; an assigning unit, which assigns the generated electronic signature to the electronic content; an electronic certificate generating unit, generating an electronic certificate, wherein the electronic certificate is associated with the electronic signature and includes signature content information; and The storage unit stores the electronic certificate in the predetermined storage unit.

Citation Information

Patent Citations

  • Electronic signature system, electronic signature client, electronic signature program, server, and electronic signature method

    JP2018067807A